logo

Foxit PDF “Flawed Design” Exploitation

ID: d825acb7-5906-584c-aec6-e49173b38347

STIX ID: report--d825acb7-5906-584c-aec6-e49173b38347

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2024-05-14

Date Updated: 2026-04-27

Author: Antonis Terefos

...
...

**Executive Summary:** Check Point Research describes a Foxit Reader-specific PDF exploitation technique that leverages a flawed user prompt workflow to trigger cmd/powershell launches and download remote payloads; the report analyzes multiple active campaigns (including APT-C-35/DoNot Team and criminal actors), details attack chains delivering downloaders, info-stealers, miners and Remcos RAT, documents builders (Python/.NET), provides YARA rules and numerous IOCs, and offers mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.